Abuse Policy

POSTA is a private transactional email system operated by ESAART Studio for ESAART-owned products and client projects whose domains are managed by ESAART Studio.

POSTA is not an open self-serve email platform. New senders, domains and API keys are manually approved before production sending is enabled.

Allowed Mail

POSTA may be used for transactional messages tied to a direct user action or relationship:

  • Account verification, magic sign-in links and password resets.
  • Receipts, invoices, subscription and billing notices.
  • Product notifications, security alerts and support replies.
  • Operational notices for users of ESAART-managed applications.

Unsolicited bulk email, purchased lists, phishing, deceptive content and third-party open relay use are prohibited.

Sender Controls

  • Every sending domain must pass DNS verification with SPF, DKIM and DMARC.
  • API keys are scoped to projects and may be restricted to a verified domain.
  • Bounces and complaints are processed through provider webhooks and suppression lists.
  • Any non-transactional notification must include an unsubscribe path.
  • Domains or projects with abusive behavior are suspended.

Report Abuse

To report unwanted or abusive email sent through POSTA, contact abuse@esaart.studio. Include full message headers and the recipient address when possible.

ESAART Studio reviews abuse reports, suppresses affected recipients when appropriate and disables senders that violate this policy.